CVE-2025-49005: Cache poisoning vulnerability in Next.js App Router
A cache poisoning vulnerability in Next.js App Router 15.3.0–15.3.2 and Vercel CLI 41.4.1–42.2.0 allowed page requests to return React Server Component payloads instead of HTML under certain conditions with middleware redirects. This could poison browser caches on Vercel and CDN caches in self-hosted deployments. The issue is resolved in Next.js 15.3.3; affected Vercel customers must redeploy their applications.
Summary
Impact
Resolution
Workarounds
Credit
References
A cache poisoning vulnerability affecting has been resolved. The issue allowed page requests for HTML content to return a React Server Component (RSC) payload instead under certain conditions. When deployed to Vercel, this would only impact the browser cache, and would not lead to the CDN being poisoned. When self-hosted and deployed externally, this could lead to cache poisoning if the CDN does not properly distinguish between RSC / HTML in the cache keys.Next.js App Router >=15.3.0 < 15.3.3 /Vercel CLI 41.4.1–42.2.0
Under specific conditions involving App Router, middleware redirects, and omitted headers, applications may:Vary
This issue occurs in environments where middleware rewrites or redirects result in improper cache key separation, because the cache-busting parameter added by the framework is stripped by the user’s redirect.
The issue was resolved in by:Next.js 15.3.3
Customers hosting on Vercel with deployments that used the impacted CLI versions must their applications to receive the fix.redeploy
Thanks to and for timely reports and debugging assistance.internal incident response teamsaffected Vercel customers
Serve RSC payloads in place of HTML
Cache these responses at the browser or CDN layer
Display broken or incorrect client content
Ensuring the header is correctly set to distinguish between different content types
Vary
Manually add the Vary header on RSC responses to differentiate between RSC and HTML payloads. Specifically, .
Vary: RSC, Next-Router-State-Tree, Next-Router-PrefetchApply a unique cache-busting search parameter to the middleware redirect destination
Source: original entry ↗
More from Vercel
Follow Vercel to get its new changes in your feed and email digest.
OpenAI Decisions API now available on AI Gateway
OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.
Timestamp attributes now supported in Vercel Flags
Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.
Glyph Cluster now available in stealth on AI Gateway
Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.